Web App Pentest
Authentication, authorization, business logic, injections, SSRF, XSS, race conditions. Black, grey and white-box.
Offensive security boutique · Brazil · Europe · US
We test web applications, APIs and AI/LLM systems the way a real attacker would — and deliver a report your board understands and your team can act on.
POST /api/v2/assistant/chat {"message": "Summarize the attached document"} → agent invokes tool export_customers() → 12,480 records returned to an anonymous user
Services
Every engagement is manual, led by a senior expert and accelerated by AI and in-house tooling.
Authentication, authorization, business logic, injections, SSRF, XSS, race conditions. Black, grey and white-box.
REST, GraphQL, gRPC and webhooks. BOLA/IDOR, mass assignment, rate limiting, JWT/OAuth, logic abuse.
Direct and indirect prompt injection, jailbreaks, data leakage via RAG, tool and agent abuse, model DoS, model supply chain.
Exposed surface, AWS/Azure/GCP configuration, Kubernetes, leaked secrets, escalation paths.
AI / LLM Pentest
AI systems create a new attack surface: natural language becomes an attack vector and every tool connected to the model becomes a path to data and actions. We test the whole system — model, prompts, RAG, tools, agents and integrations — with a reproducible PoC for every finding.
Test my AI systemWhy Pentest Machine
Every test is run by professionals holding OSCP, OSWE, OSEP, CRTO e BSCP with a track record in bug bounty and published CVEs.
AI agents and internal tooling widen recon and triage coverage, freeing the expert for what needs creativity: logic, chaining and exploitation.
Executive summary for the board, technical detail with PoC for the team, a prioritized remediation plan and a retest included in the price.
Methodology
Rules of engagement, testing windows, emergency contacts.
Surface mapping with AI and in-house tooling.
Manual, creative, chained. Critical alerts within 24h.
Real business impact, not just CVSS.
Executive + technical, PoC and remediation plan.
Fix validation and final attestation.
“In three days the team chained an authorization flaw in the API with a prompt injection in our assistant and reached customer data. The report was straight to the point, the board understood the risk on first read, and the retest confirmed the fixes before our PCI audit.”
Frequently asked questions
It depends on scope: number of applications, endpoints, authenticated functionality and whether AI systems are involved. A mid-size web application pentest usually takes 5 to 15 working days. We send a fixed-price proposal within 24h of understanding the scope.
A scanner automates the search for known patterns and produces false positives. A pentest is run by an expert who exploits logic flaws, chains vulnerabilities and proves real impact with a PoC — which PCI-DSS, SOC 2 and ISO 27001 audits expect.
Security testing of chatbots, copilots and agents: direct and indirect prompt injection, data leakage via RAG, tool and agent abuse, jailbreaks and model DoS, following the OWASP Top 10 for LLM and MITRE ATLAS. We test the whole system, not just the model.
Yes. Once your team fixes the findings, we validate the fixes and issue a final attestation — at no extra cost, within 90 days of report delivery.
Yes. We sign an NDA before any scope detail, work in English, Portuguese and Spanish, and invoice in the US, the EU or Brazil.
Blog
From the blog: offensive security in practice.
Request a quote
Tell us what you need tested. An expert — not a salesperson — replies with scope, timeline and price.